Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt, a key provider of free TLS certificates, has rolled out short-lived and IP address-based certificates for general use. These new options became available starting in early 2026, addressing …

Argus – Python-powered Toolkit for Information Gathering and Reconnaissance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Argus is a comprehensive Python-based toolkit designed for reconnaissance tasks in cybersecurity. The developers recently released version 2.0, expanding it to include 135 modules. This tool consolidates network analysis, web …

Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Vertex AI contains default configurations that allow low-privileged users to escalate privileges by hijacking Service Agent roles. XM Cyber researchers identified two attack vectors in the Vertex AI Agent …

Researchers Gain Access to StealC Malware Command-and-Control Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers successfully exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels and exposing a threat actor’s identity through their own stolen session cookies. The breach …

Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time …

Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has confirmed active exploitation of a critical zero-day remote code execution vulnerability in its Secure Email Gateway and Secure Email and Web Manager appliances. Tracked as CVE-2025-20393, the flaw …

Google Rolls Out Long-Awaited @gmail.com Email Change Feature for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google is gradually rolling out the ability to change the @gmail.com email address associated with a Google Account to a new @gmail.com address. This feature, previously unavailable, addresses a common …

Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Go programming language team has rolled out emergency point releases, Go 1.25.6 and 1.24.12, to address six high-impact security flaws. These updates fix denial-of-service (DoS) vectors, arbitrary code execution …

New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical misconfiguration in AWS CodeBuild enabled unauthenticated attackers to seize control of key AWS-owned GitHub repositories, including the widely used AWS JavaScript SDK powering the AWS Console itself. This …